VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 22 of 82
  • CVE-2026-2896HigFeb 22, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely.…

  • CVE-2025-13808HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/UserController.java of the component User Profile…

  • CVE-2025-13806HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Transaction…

  • CVE-2025-11030HigSep 26, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837a60. Impacted is an unknown function of the file /admin/all-applied-leave.php of the component HTTP Request Handler. The manipulation results in improper…

  • CVE-2025-10374HigSep 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Shenzhen Sixun Business Management System 7/11. This affects an unknown part of the file /Adm/OperatorStop. Performing manipulation results in improper authorization. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2025-54378HigJul 26, 2025
    risk 0.47cvss 8.3epss 0.00

    HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API endpoints do not perform authorization checks when interacting with a resource. Both the JS and PHP…

  • CVE-2025-5522HigJun 3, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The…

  • CVE-2025-30117HigMar 18, 2025
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. After bypassing the device pairing, an attacker can obtain sensitive user and…

  • CVE-2025-24053HigMar 13, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-1815HigMar 2, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The manipulation of the argument user_cookie leads to improper authorization. It is possible to initiate the attack…

  • CVE-2025-0484HigJan 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown processing of the file /fladmin/sysconfig_doedit.php of the component Backend. The manipulation leads to improper authorization. The attack may be initiated…

  • CVE-2025-21348HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.02

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-36438HigJul 15, 2024
    risk 0.47cvss 7.3epss 0.00

    eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other attacks.

  • CVE-2024-39597HigJul 9, 2024
    risk 0.47cvss 7.2epss 0.00

    In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and registration is activated, without requiring the merchant to approve the account beforehand. If the site is not configured as…

  • CVE-2022-34405HigJan 26, 2023
    risk 0.47cvss 7.3epss 0.00

    An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to the process to elevate privileges on the…

  • CVE-2022-4811HigDec 28, 2022
    risk 0.47cvss 8.3epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

  • CVE-2022-26310HigAug 1, 2022
    risk 0.47cvss 7.3epss 0.01

    Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. The impact could lead to a vertical privilege escalation…

  • CVE-2021-36784HigMay 2, 2022
    risk 0.47cvss 7.2epss 0.01

    A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.

  • CVE-2021-31384HigOct 19, 2021
    risk 0.47cvss 7.2epss 0.01

    Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can…

  • CVE-2019-7479HigDec 31, 2019
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen 5 version 5.9.1.12-4o and earlier, Gen 6 version 6.2.7.4-32n, 6.5.1.4-4n, 6.5.2.3-4n, 6.5.3.3-3n, 6.2.7.10-3n, 6.4.1.0-3n,…